CVE-2004-2734: Critical severity Novell NetWare FTP Server vulnerability
Published Dec 31, 2004
·Updated
webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.
Affected Software
4 affected components
Novell NetWare FTP Server=6.5-sp1
Novell NetWare FTP Server=6.5-sp1.1a
Novell NetWare FTP Server=6.5-sp1.1b
Novell NetWare FTP Server=6.5
Event History
Dec 31, 2004
CVE Published
05:00 AM
Oct 9, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2734?
CVE-2004-2734 has a high severity rating due to the potential for unauthorized access to protected directories.
2
How do I fix CVE-2004-2734?
To fix CVE-2004-2734, you should correct the alias tag configuration in webadmin-apache.conf to ensure consistent casing.
3
What products are affected by CVE-2004-2734?
CVE-2004-2734 affects Novell NetWare 6.5, including service packs 1, 1a, and 1b.
4
What kind of attack can exploit CVE-2004-2734?
CVE-2004-2734 can be exploited by remote attackers to gain unauthorized access to the WEB-INF folder.
5
When was CVE-2004-2734 published?
CVE-2004-2734 was published on December 23, 2004.